CVE-2019-1907
Severity
8.8HIGH
EPSS
0.1%
top 64.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 21
Latest updateMay 24
Description
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker with read-only privileges t…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-34x5-95ff-w3cg: A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive confi↗2022-05-24
CVEList▶
Cisco Integrated Management Controller Substring Comparison Privilege Escalation Vulnerability↗2019-08-21
📋Vendor Advisories
1Cisco▶
Cisco Integrated Management Controller Substring Comparison Privilege Escalation Vulnerability↗2019-08-21